Connect incident alerts to an evidence search
When Better Stack sends an incident to Notis, search Rkvst for matching events and bring potential evidence into the response.
Trigger
Webhook received
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Action
Search Events
Tool to search events matching filter criteria with pagination. use when retrieving events by odata filter and paging through large result sets.
Why this helps
Switching between incident alerts and evidence records makes it easier to miss useful context.
- Start an evidence search from the incident signal.
- Reduce the back-and-forth between monitoring and evidence tools.
- Give the responder a concise set of potential matches.
Setup
Build it in a few focused steps.
- 1Connect Better Stack and Rkvst to Notis once through the portal.
- 2Create an automation in the portal or ask Notis to build it conversationally.
- 3Write one prompt asking Notis to use each incident's details as criteria for a Rkvst event search and summarize likely matches.
- 4Select an incoming webhook trigger and choose a channel for run reports.
- 5Send one real incident through the webhook and review whether the returned events are useful.
Questions about this workflow
How does Better Stack start the workflow?
Better Stack or a custom backend sends an HTTP request to the Notis webhook when it reports an incident.
Does this write evidence into Rkvst?
No. The selected action searches events and returns matches for review.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Better stack to Rkvst. A trigger fires from one place; an action lands in another.
Better stack triggers
Rkvst actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Download Event Attachment
Tool to download an attachment from a specified event on an asset. use when you have asset uuid, event uuid, and attachment uuid, and want the raw binary content.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get App Registration
Tool to retrieve details for a given app registration id. use after obtaining the application's uuid to inspect its configuration and credentials.
Get Asset
Tool to retrieve details for a given asset. use after you have its uuid; set `at time` to get historical state.
Get Blob
Tool to retrieve details of a blob by id. use after confirming the blob id.
Get Event
Tool to retrieve details of a specified event. use when you need full metadata, attributes, and associated trails of an existing event in datatrails.
Get IAM Subject
Tool to retrieve iam subject details. use when you need to fetch details for a specific iam subject by its id.
Get Member
Tool to retrieve details for a given member id. use after obtaining a valid member uuid.
Get Public Asset
Tool to retrieve details for a public asset. use when you have a public asset uuid.
Connect any two apps with Notis in the middle.
Better stack and Rkvst, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Rkvst.